https://seclists.org/oss-sec/2026/q3/954: CVE-2026-86507: Apache Roller: Stod XSS in comment moderation via comment author URL
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Apache Roller=6.1.5
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Apache Roller 6.1.5 deployments are affected if comments are permitted on at least one weblog. No non-default server configuration is required.
2
What must an attacker do to exploit it?
An unauthenticated remote attacker must submit a comment containing a crafted comment-author URL. The stored script executes only when a weblog moderator or global administrator views the comment management page.
3
What is the impact if exploitation succeeds?
The crafted script can execute in the session of the moderator or global administrator reviewing the comment. The provided CVSS vector indicates impacts to confidentiality and integrity, with no availability impact.
4
What should organizations do if they use the affected release?
Upgrade Apache Roller to version 6.1.6 or later. If an immediate upgrade is not possible, disabling comments on all weblogs removes the stated exposure condition.